Privacy Policy

Last updated: 6 July 2026

Tesera Studio OÜ, a private limited company registered in Estonia at Sepapaja tn 6, 15551 Tallinn, Harju Maakond ("Tesera Studio", "we", "us"), designs and publishes mobile apps under its own brand. This policy explains what personal data we collect, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR). For the data described here, Tesera Studio is the data controller.

This policy covers both our website at teserastudio.com and the mobile apps we publish, including Open Signal: Cell Tower Finder ("Open Signal") (each, an "App"). Where a particular App handles data differently, the App-specific section below governs.

The short version

  • We do not sell or rent your personal data.
  • Our apps do not require an account, and we do not show ads inside them.
  • Optional subscriptions are billed by Apple — we never see your payment details.
  • Our apps collect only what they need to work, plus limited usage data that is not linked to your identity, so we can improve them.
  • You can contact us at any time to exercise your privacy rights.

1. Our website

This website is largely static. You do not need an account to use it. When you visit, our hosting provider records standard server logs — your IP address, browser type, the page requested, and a timestamp. We rely on these logs only to keep the site secure and reliable, on the legal basis of our legitimate interest in operating a safe and stable service. Logs are retained for a short period and then deleted or anonymised. This site does not use advertising or tracking cookies.

2. Email contact

If you write to us at info@teserastudio.com, we use your message and email address solely to read and reply to you. We do not add you to any mailing list, and we keep the correspondence only for as long as needed to handle your enquiry and any reasonable follow-up.

3. Our apps

Open Signal helps you see nearby cell towers and coverage and understand the mobile signal your device is receiving. To do that, the App works with the data below. Other apps we publish follow the same principles, and each will have its own notes added to this section when it launches.

3.1 Location

The App asks for permission to access your device location. We use your location to show your position, to find cell towers and coverage near you, and to display the strength of the signal where you are. You can grant or deny this permission and change it at any time in iOS Settings; without it, location-based features will not work. When you look up towers near you, your approximate coordinates may be sent to our backend so it can return relevant results. We do not use your location to identify you, and we do not build a profile of your movements.

3.2 Cellular and network information

To do its job, the App reads technical information your device exposes about the mobile network — such as the network operator, signal strength, connection type, and cell identifiers (for example MCC, MNC, and cell ID). This is used to identify the tower you are connected to and to show you signal details. It is technical network information, not data about who you are.

3.3 Reference data from our backend

Information about cell towers and coverage is stored in our backend, which is hosted on Supabase, and the App queries it to show you results. This reference data describes towers and networks, not you. It may be derived from publicly available datasets and measurements.

3.4 Usage and diagnostic data

We collect limited, aggregated usage data to understand how features are used and to optimise the App. This is configured so that it is not linked to your identity. The App has no account, so we do not collect your name, email address, or login credentials through it.

3.5 Purchases and subscriptions

The App offers an optional paid subscription ("Pro"). Payment is handled entirely by Apple through your App Store account — we never see or store your payment details. To unlock and restore your subscription we use RevenueCat, a subscription management service, which records your purchase history and subscription status against an anonymous, app-generated identifier. There is no account and this data is not linked to your identity; we use it only to make Pro features work and to understand overall subscription performance.

3.6 Advertising attribution (App Tracking Transparency)

We may advertise the App on the App Store using Apple Search Ads, and we want to know which campaign brought a new user to us. For that, the App shows Apple's App Tracking Transparency ("ATT") prompt asking for permission to track. The App works exactly the same whether you allow or deny. If you allow, Apple's advertising identifier (IDFA) and Apple's AdServices attribution token are used — via RevenueCat — to link your install to the ad campaign that led you to the App. If you deny, we receive only Apple's standard, non-identifying attribution. This campaign measurement is the only "tracking" the App performs, and you can change your choice at any time in iOS Settings → Privacy & Security → Tracking.

4. Analytics and error reporting

We use two service providers to keep our apps reliable:

  • PostHog — product analytics, so we can see which features are used and where people get stuck and improve the experience. We configure it to avoid collecting information that identifies you personally.
  • Sentry — error and crash reporting, which sends us diagnostic information when something goes wrong (such as the error, the device model, and the operating system version) so we can fix it.

We do not display ads inside our apps, and neither PostHog nor Sentry is used for advertising. The only advertising-related processing we do is the Apple Search Ads campaign measurement described in section 3.6, which runs only with your App Tracking Transparency consent. We never sell your personal data.

5. Legal bases for processing

Under the GDPR, we rely on the following legal bases:

  • Consent — for accessing your device location and for advertising attribution, each of which you grant through the corresponding iOS permission prompt and can withdraw at any time in iOS Settings.
  • Legitimate interest — for keeping our website and apps secure and reliable, and for improving them through non-identifying analytics and error reports.
  • Legal obligation — where we must process data to comply with the law.

6. Who we share data with

We keep our supply chain small. We rely on the following processors and sub-processors, each acting on our behalf:

  • Vercel — website hosting and the server logs described above.
  • Supabase — backend and database for our apps.
  • PostHog — product analytics.
  • Sentry — error and crash reporting.
  • RevenueCat — in-app subscription management and restore, and the Apple Search Ads attribution described in section 3.6.
  • Apple — distributes our apps through the App Store, processes all in-app payments (we never receive your payment details), and, where you opt in through your Apple settings, provides us with limited, aggregated App Store analytics.

We do not share your data with anyone else except where we are legally required to do so. Some of these providers may process data outside Estonia; where that happens, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

7. Data retention

We keep data only for as long as it is needed for the purpose it was collected. Website logs are retained briefly and then deleted or anonymised. Analytics and error-reporting data are kept only as long as they are useful for understanding and improving the apps, and are then deleted or aggregated. Email correspondence is kept for as long as needed to handle your enquiry.

8. Children

Our website and apps are intended for a general audience and are not directed to children under 13. We do not knowingly collect personal data from children.

9. Security

We take reasonable technical and organisational measures to protect the data we handle. Data travelling between our apps and our backend is sent over encrypted connections, and we limit access to the information we hold. No system is perfectly secure, but we work to keep the risk low.

10. Your rights

Under the GDPR, you may ask us at any time to:

  • confirm whether we hold personal data relating to you, and receive a copy of it;
  • correct information that is inaccurate or incomplete;
  • delete your data, or restrict how we use it;
  • object to processing that is based on our legitimate interest;
  • receive certain data in a portable format.

Because our apps have no account and we do not link usage data to your identity, there may be cases where we genuinely cannot single out the data relating to you specifically — but we will always help wherever we can. To exercise any of these rights, email info@teserastudio.com. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

11. Changes

We will revise this policy as the studio and its apps evolve. The "Last updated" date at the top reflects the current version, and we will post any material changes on this page.

12. Contact

Questions about this policy? Reach us at info@teserastudio.com.